| Cybersecurity |
Protecting systems, networks, and data from cyber threats. |
| CIA Triad |
Three core security principles. |
| Confidentiality |
Only authorized users can access data. |
| Integrity |
Data remains accurate and unaltered. |
| Availability |
Systems and data remain accessible when needed. |
| Authorization |
Grants permitted access to resources. |
| Authentication |
Verifies a user’s identity. |
| Digital Asset |
Valuable digital information or resource. |
| Vulnerability |
A weakness that can be exploited. |
| Threat |
Anything capable of causing harm. |
| Countermeasure (Control) |
A safeguard that reduces risk. |
| Brute Force Attack |
Tries every possible password. |
| Dictionary Attack |
Uses common password lists. |
| Credential Stuffing |
Uses leaked credentials on other sites. |
| Sniffing |
Capturing network traffic. |
| DoS / DDoS |
Flooding a service to make it unavailable. |
| Spoofing |
Faking an identity or address. |
| Phishing |
Fake messages to steal information. |
| Smishing |
Phishing using SMS messages. |
| Vishing |
Phishing through phone calls. |
| Social Engineering |
Manipulating people into revealing information. |
| Identity Theft |
Stealing someone’s personal identity. |
| Session Hijacking |
Taking over an active user session. |
| Keylogger |
Records keystrokes secretly. |
| Spyware / Adware |
Software that spies or shows unwanted ads. |
| Virus |
Malware that attaches to files. |
| Worm |
Malware that spreads automatically. |
| Trojan |
Malware disguised as legitimate software. |
| Ransomware |
Encrypts files and demands payment. |
| Rootkit |
Hides malicious activity on a system. |
| Zero-Day Exploit |
Exploits an unknown vulnerability. |
| SQL Injection |
Injects SQL commands into applications. |
| Hacker |
A person who tests or exploits systems. |